PT-2023-31871 · Jetbrains · Intellij Idea
Published
2023-12-21
·
Updated
2023-12-29
·
CVE-2023-51655
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
JetBrains IntelliJ IDEA versions prior to 2023.3.2
Description
Code execution was possible in Untrusted Project mode via a malicious plugin repository specified in the project configuration.
Recommendations
For versions prior to 2023.3.2, update to version 2023.3.2 or later to resolve the issue. As a temporary workaround, consider restricting access to untrusted plugin repositories in the project configuration until the update is applied.
Fix
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Intellij Idea